URLhaus Database

You are currently viewing the URLhaus database entry for http://194.49.94.67/files/get4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728931
URL: http://194.49.94.67/files/get4.exe
URL Status:Offline
Host: 194.49.94.67
Date added:2023-11-08 09:13:13 UTC
Last online:2023-11-12 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-08 09:14:06 UTC to madhost{at}tutanota[dot]com)
Takedown time:4 days, 10 hours, 53 minutes Bad (down since 2023-11-12 20:07:34 UTC)
Tags:32 exe PrivateLoader Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-12n/aexe cc54075055057cc8c0de185f7fea71146bb0a8424d3dbd18ca1219c29ff706bdVirustotal results 39.44%PrivateLoader
2023-11-11n/aexe 79c5529100559ce0b118619b0fc1f8bd7ceb037aa2bd278498b7c75394eacf3an/a 
2023-11-11n/aexe 2098861183af17f90540b06c78ca66f03cf2a33ddde87f1649fdec0e85270f48n/aSmoke Loader
2023-11-10n/aexe 67c8c2aa16bc4a0da7b2d121808e2971ef4ac58f1ba1a048511ade93c5a8e5den/aSmoke Loader
2023-11-09n/aexe cccc4690ace16e44f44473c2df179b5b17e27f863b33abda126199014cb224d8Virustotal results 40.58%Smoke Loader
2023-11-08n/aexe 923c7929978a6fe09d671392ecceb643021ff9940b2b9c8522c7f6bbc89f9790Virustotal results 26.39%Smoke Loader
2023-11-08n/aexe 0307f62772ac2e241d4e3e4a7feda4a82508615e2459037da9be3486411ab514n/a Smoke Loader
2023-11-08n/aexe 6ed28a9b3edd3bb9ed39a3e4d62c686e8761afa45a412b72cb43851de9643f14Virustotal results 22.54%PrivateLoader